CVE-2019-17223Cross-site Scripting in Dolibarr

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 42.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateMay 24

Description

There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Packagistdolibarr/dolibarr< 11.0.1

🔴Vulnerability Details

4
GHSA
Dolibarr ERP and CRM HTML Injection2022-05-24
OSV
Dolibarr ERP and CRM HTML Injection2022-05-24
CVEList
CVE-2019-17223: There is HTML Injection in the Note field in Dolibarr ERP/CRM 102019-10-15
OSV
CVE-2019-17223: There is HTML Injection in the Note field in Dolibarr ERP/CRM 102019-10-15
CVE-2019-17223 — Cross-site Scripting in Dolibarr | cvebase